All sites should have the following books or information available when setting up auditing:
Trusted Solaris 8 4/01 Release Notes
Describes any late-breaking news about auditing, including known problems.
Trusted Solaris Administrator's Procedures
Describes administration tasks, such as assuming a role, in detail.
Your site security policy
Describes the security policy and security procedures at your site.
Other books on auditing that may be useful include:
A Guide to Understanding Audit in Trusted Systems
Auditing in a UNIX System
DoD Trusted Computer System Evaluation Criteria (the Orange Book)
Compartmented Mode Workstation Evaluation Criteria
Guideline for Trusted Facility Management and Audit, Virgil D. Gligor, 1985
Common Criteria for Information Technology Security Evaluation, Version 2.1, August 1999. For online information, see http://csrc.ncsl.nist.gov/cc/ccv20/ccv2list.htm.